DEV Community

Discussion on: Setting Up Authorization for HTTP Cloud Functions in GCP

Collapse
 
farmanabbasi profile image
Mohammad Farman Abbasi

One thing i am not understanding, if someone is having access to the caller function, they can get the AUTH token and if they got the AUTH token they can access our secured called function. Then how is that secure as the caller function allows unauthenticated access to get the token. Someone please clarify I am not getting this answer for a while now. Thank you.